期刊文献+

KCapISO:一种基于HybridHP的宏内核操作系统载入模块权能隔离方案 被引量:1

KCapISO:A HybridHP-Based Capability Isolation Method of Loaded Modules on Monolithic Kernel Operating System
下载PDF
导出
摘要 宏内核操作系统提供对第3方模块和驱动程序等载入模块的支持,允许载入模块运行在内核态特权级.由于运行在最高特权级,载入模块对内核的核心服务的关键对象的访问难以得到系统的有效控制.考虑对被监控系统的性能影响控制在很小的范围,基于内嵌式的监控机制HybridHP,提出了一种宏内核架构下的载入模块权能隔离方案KCapISO,为内核和载入模块维护各自的页表,从权能上将两者隔离,确保载入模块无法修改内核的数据,并且无法以任何方式直接调用或跳转到内核中执行,这些动作都需经过KCapISO的监控和检查.实验结果表明,KCapISO能有效地将内核与载入模块在权能上相互隔离,同时获得较好的系统性能. The monolithic kernel operating systems provide support for the loaded modules, such as third-party modules and drivers. Due to that the loaded modules run on the privilege level, the access to the key objects of core services within the kernel is difficult to be controlled effectively. Considering little influence on the performance of the monitored system, based on the embeddedstyle monitoring system HybridHP, we propose a capability isolation method of loaded modules on the monolithic kernel operating system, named KCapISO. KCapISO maintains the respective page tables for the kernel and loaded modules, which are isolated from the aspect of the capability. KCaplSO ensures that the loaded modules cannot modify the kernel data, and cannot directly call or jump into the kernel in any way. And these behaviors are required to pass through monitoring and inspection by KCapISO. The experiment result shows that KCapISO effectively isolates the kernel and loaded modules from the aspect of the capability, and achieves good system performance.
出处 《计算机学报》 EI CSCD 北大核心 2016年第3期552-561,共10页 Chinese Journal of Computers
基金 国家自然科学基金(61402057) 江苏省科技计划自然科学基金(BK20140418) 中国博士后科学基金(2015M571737) 江苏省"六大人才高峰"高层次人才基金(2011-DZXX-035) 江苏省高校自然科学研究基金(12KJB520001)资助~~
关键词 宏内核操作系统 载入模块 硬件虚拟化 权能隔离 安全监控 monolithic kernel operating system loaded module hardware virtualization capability isolation security monitoring
  • 相关文献

参考文献14

  • 1Liedtke J. On wkernel construction//Proceedings of the 15th ACM Symposium on Operating System Principles. New York, USA, 1995:237-250. 被引量:1
  • 2Garfinkel T, Rosenblum M. A virtual machine introspection based architecture for intrusion detection//Proceedings of the 10th Symposium on Network and Distributed System Security. San Diego, USA, 2003:191-206. 被引量:1
  • 3Seshadri A, Luk M, Qu N, et al. SeeVisor: A tiny hypervisor to provide lifetime kernel code integrity for commodity OSes// Proceedings of the 2Ist ACM Symposium on Operating Systems Principles. Stevenson, USA, 2007:335 -350. 被引量:1
  • 4Riley R, Jiang X, Xu D. Guest-transparent prevention of kernel rootkits with VMM based memory shadowing// Proceedings of the llth Recent Advances in Intrusion Detection. Boston, USA, 2008:1-20. 被引量:1
  • 5Sharif M, Lee W, Cui W, et al. Secure In-VM monitoring using hardware virtualization//Proceedings of the 16th ACM Conference on Computer and Communications Security. Chicago, USA, 2009:477-487. 被引量:1
  • 6Srivastava A, Giffin J. Efficient monitoring of untrusted kernel-mode execution//Proeeedings of the 18th Symposium on Network and Distributed System Security. San Diego, USA, 2011. 被引量:1
  • 7Xiong X, Tian D, Liu P. Practical protection of kernel integrity for commodity OS from untrusted extensions// Proceedings of the 18th Symposium on Network and Distributed System Security. San Diego, USA, 2011. 被引量:1
  • 8Xiang G, Jin H, Zou D. A comprehensive monitoring frame work for virtual computing environment//Proceedings of the 2012 International Conference on Information Networking. Piscataway, USA, 2012:551-556. 被引量:1
  • 9Cao Y, Liu J, Miao Q, et al. Osiris: A malware behavior capturing system implemented at virtual machine monitor layer//Proceedings of the 8th International Conference on Computational Intelligence and Security. Piseataway, USA, 2012:534-8. 被引量:1
  • 10李博,沃天宇,胡春明,李建欣,王颖,怀进鹏.基于VMM的操作系统隐藏对象关联检测技术[J].软件学报,2013,24(2):405-420. 被引量:21

二级参考文献15

  • 1怀进鹏,李沁,胡春明.基于虚拟机的虚拟计算环境研究与设计[J].软件学报,2007,18(8):2016-2026. 被引量:78
  • 2Barham P, Dragovic B, Fraser K, Hand S, Harris T L, Ho A, Neugebauer R, Pratt I, Warfield A. XEN and the art of virtualization//Proceedings of the 19th ACM Symposium on Operating Systems Principles (SOSP'03). New York, 2003: 164-177. 被引量:1
  • 3Kivity A, Kamay Y, Laor D, Lublin U, Liguori A. KVM: The Linux virtual machine monitor//Proceedings of the 2007 Ottawa Linux Symposium. Ottawa, 2007:225-230. 被引量:1
  • 4Garfinkel T, Rosenblum M. A virtual machine introspection based architecture for intrusion detection//Proceedings of the 10th Network and Distributed System Security Symposium (NDSS'03). San Diego, 2003:191-206. 被引量:1
  • 5Grizzard J. Towards self-healing systems: Re-establishing trust in compromised systems[Ph. D. dissertation]. Georgia Institute of Technology, Atlanta, Georgia, 2006. 被引量:1
  • 6Jiang X, Wang X, Xu D. Stealthy malware detection through VMM-based " Out-Of-the-Box" semantic view reconstruc- tion//Proceedings of the 14th ACM Conference on Computer and Communications Security ( CCS ' 07). Alexandria, VA, 2007. 128-138. 被引量:1
  • 7Lanzi A, Sharif M, Lee W. K-Tracer: A system for extrac- ting kernel malware behavior//Proceedings of the 16th Network and Distributed System Security Symposium (NDSS'09). San Diego, 2009. 被引量:1
  • 8Payne B D, Carbone M, Sharif M I, Lee W. Lares: An ar- chitecture for secure active monitoring using virtualization// Proceedings of the 29th IEEE Symposium on Security and Privacy(S~P'08). Oakland, California, 2008:233-247. 被引量:1
  • 9Riley R, Jiang X, Xu D. Guest-transparent prevention of kernel rootkits with VMM-based memory shadowing//Pro- ceedings of the llth Recent Advances in Intrusion Detection (RAID'08). Boston, MA, 2008:1-20. 被引量:1
  • 10Seshadri A, Luk M, Qu N, Perrig A. SecVisor: A tiny hy- pervisor to provide lifetime kernel code integrity for commod- ity OSes//Proeeedings of the 21st ACM Symposium on Oper- ating Systems Principles(SOSP'07). Stevenson, WA, 2007: 335-350. 被引量:1

共引文献21

同被引文献9

引证文献1

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部